File size: 1,255 Bytes
72a4e50
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# ipsec.conf - strongSwan IPsec configuration file

config setup
	uniqueids=no
	charondebug="cfg 2, dmn 2, ike 2, net 0"

conn %default
	dpdaction=clear
	dpddelay=300s
	rekey=no
	left=%defaultroute
	leftfirewall=yes
	right=%any
	ikelifetime=60m
	keylife=20m
	rekeymargin=3m
	keyingtries=1
	auto=add

#######################################
# L2TP Connections
#######################################

conn L2TP-IKEv1-PSK
	type=transport
	keyexchange=ikev1
	authby=secret
	leftprotoport=udp/l2tp
	left=%any
	right=%any
	rekey=no
	forceencaps=yes

#######################################
# Default non L2TP Connections
#######################################

conn Non-L2TP
	leftsubnet=0.0.0.0/0
	rightsubnet=10.0.0.0/24
	rightsourceip=10.0.0.0/24

#######################################
# EAP Connections
#######################################

# This detects a supported EAP method
conn IKEv2-EAP
	also=Non-L2TP
	keyexchange=ikev2
	eap_identity=%any
	rightauth=eap-dynamic

#######################################
# PSK Connections
#######################################

conn IKEv2-PSK
	also=Non-L2TP
	keyexchange=ikev2
	authby=secret

# Cisco IPSec
conn IKEv1-PSK-XAuth
	also=Non-L2TP
	keyexchange=ikev1
	leftauth=psk
	rightauth=psk
	rightauth2=xauth